Impact
An unauthenticated command injection flaw exists in the infosrvd service that listens on UDP port 9992. A remote attacker can craft a UDP packet and cause the service to execute arbitrary shell commands with root privileges. The vulnerability results from a hardcoded salt for authentication and an all‑zero wildcard MAC bypass, rendering the authentication mechanism ineffective. The weakness is a classic OS command injection (CWE-78) and a broken authentication approach (CWE-321).
Affected Systems
Affected devices include Zbtlink models WE1326, WE357, WE5926, WE5926‑WD, WE826‑Q, WE826‑T2, WE826‑WD, WG108, WG3526 (firmware 19.1101 or later), Zbtlink WE2426‑C (firmware 19.1112), Zbtlink WE5926‑EC_QP (firmware 20.0516), Zbtlink WF3526‑P (firmware 19.051) and Unsure: CTN720‑W1, LF‑1541, MT7620N (firmware 19.1101), and WRC1 (firmware 20.0622). These devices use the infosrvd service that is exposed to the network without adequate authentication. If the affected firmware is in use, the device is vulnerable.
Risk and Exploitability
The CVSS score is 9.3, indicating high severity. EPSS is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. The exploitation requires only a crafted UDP packet to the exposed port, and no authentication or other pre‑conditions are needed. Given the simplicity of the attack vector, the threat is significant for any network that accepts packets on port 9992 to these devices.
OpenCVE Enrichment